MidnightBSD

Advisories for wiccle

CVE-2010-3208 MEDIUM

Cross-site scripting (XSS) vulnerability in ajax.php in Wiccle Web Builder (WWB) 1.00 and 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the post_text parameter in a site custom_search action to index.php. NOTE: some of these details are obtained from third party information.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
wiccle wiccle_web_builder 1.00
wiccle wiccle_web_builder 1.0.1